← Vulnerability feed

Vulnerability record · CVE-2020-3569 · published 23 September 2020

CVE-2020-3569: Cisco IOS XR DVMRP IGMP packet handling memory exhaustion

Cisco · Ios Xr

Cisco IOS XR Software mishandles IGMP packets in its Distance Vector Multicast Routing Protocol (DVMRP) feature, allowing crafted traffic to crash the IGMP process or exhaust device memory. Because the affected process can drag down other processes such as interior and exterior routing protocols, a single remote packet stream can destabilize routing on the device.

8.6 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 3.3% · top 11.9% CWE-400 · Uncontrolled resource consumptionCWE-770 · Allocation without limits
8.6CVSS 3.1 base score, v2 5.0
3.3%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to immediately crash the IGMP process or cause memory exhaustion, resulting in other processes becoming unstable. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address these vulnerabilities.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityRemote, unauthenticated denial of service with CISA KEV exploitation evidence and a CVSS base of 8.6, though impact is availability-only and EPSS probability is modest.

What it is

Cisco IOS XR Software mishandles IGMP packets in its Distance Vector Multicast Routing Protocol (DVMRP) feature, allowing crafted traffic to crash the IGMP process or exhaust device memory. Because the affected process can drag down other processes such as interior and exterior routing protocols, a single remote packet stream can destabilize routing on the device.

Impact

An unauthenticated remote attacker can immediately crash the IGMP process or drive memory exhaustion that makes other processes, including routing protocols, unstable. The result is denial of service on the affected device rather than code execution or data exposure.

Attack surface

Reachable over the network by sending crafted IGMP traffic to an affected device; the CVSS vector shows no privileges and no user interaction required. DVMRP must be relevant to the device's configuration for the vulnerable code path to be exercised.

Exploitation

CVE-2020-3569 is listed in CISA's Known Exploited Vulnerabilities catalog with a 2021-11-03 addition date, indicating exploitation in the wild; EPSS gives a 30-day probability of about 3.3 percent (88th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Cisco IOS XR software updates referenced in the vendor advisory cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz.
  • If DVMRP is not required, disable the DVMRP feature to remove the vulnerable code path.
  • Restrict IGMP and multicast traffic to trusted network segments using infrastructure ACLs and multicast boundary controls.
  • Monitor device memory and process health for the IGMP process and routing protocol processes to catch early exhaustion.
  • Track CISA KEV remediation due date (2022-05-03) and confirm patched status across the fleet.

Detection

  • Alert on IGMP process crashes or restarts in IOS XR logs and syslog.
  • Monitor device memory utilization trends for unexplained growth correlated with multicast traffic.
  • Watch for routing protocol process instability or adjacency flaps following multicast traffic bursts.
  • Baseline and inspect inbound IGMP traffic volumes and sources at network edges for anomalies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-3569 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3569 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-3118Cisco IOS XR CDP packet parsing flaw allows adjacent code executionCisco IOS XR's Cisco Discovery Protocol implementation fails to properly validate string input in certain CDP message fields, allowing a stack overfl…KEVEPSS 12%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.6CVE-2020-3566Cisco IOS XR DVMRP IGMP queue flaw causes memory exhaustionCisco IOS XR Software mishandles queue management for IGMP packets in its DVMRP feature, allowing uncontrolled memory consumption. An unauthenticated…KEVEPSS 3.7%analysed8.0CVE-2018-0175Cisco IOS, IOS XE and IOS XR LLDP format string flawA format string vulnerability exists in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.5%analysed7.5CVE-2016-6415Cisco IOS IKEv1 memory disclosure via SA negotiationThe IKEv1 server implementation in Cisco IOS, IOS XE, IOS XR and PIX mishandles Security Association negotiation requests, allowing a remote attacker…KEVEPSS 88%analysed7.5CVE-2010-3035Cisco IOS XR BGP peering reset via unrecognized transitive attributeCisco IOS XR 3.4.0 through 3.9.1 mishandles unrecognized transitive BGP attributes when BGP is enabled, allowing a crafted prefix announcement to res…KEVEPSS 5.7%analysed6.5CVE-2022-20821Cisco IOS XR health check RPM exposes Redis port without authenticationThe health check RPM in Cisco IOS XR Software opens TCP port 6379 by default when activated, exposing the Redis instance inside the NOSi container. A…KEVEPSS 11%analysed5.9CVE-2009-2055Cisco IOS XR BGP invalid attribute causes session reset DoSCisco IOS XR 3.4.0 through 3.8.1 fails to properly validate a BGP UPDATE message attribute, allowing a remote peer to reset BGP sessions. Because BGP…KEVEPSS 3.3%analysed

Source: NIST National Vulnerability Database (record CVE-2020-3569), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.